27 comments

  • hypfer 9 minutes ago

    This is stuff on the level of O&O ShutUp10. Which is a good tool, but also, a Windows tool for very (back in the day) Windows-specific nonsense.

    What's going on at Apple product strategy?

  • bigyabai 32 minutes ago

    Something horrible must have happened, if macOS users are curling shell scripts from the internet to make their desktops more like Linux.

      trollbridge 8 minutes ago

      curl|bash is now standard way to install packages on both macOS and Linux. It’s maddening, but it is now.

        pjmlp 5 minutes ago

        Meanwhile on Windows we mostly use the store or winget, funny times.

      drnick1 5 minutes ago

      Uncomfortable, but true.

      GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.

      nomel 19 minutes ago

      Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).

        trollbridge 7 minutes ago

        People with 256GB laptops care when the 27 AI stuff burns up 10-20% of their storage.

          GeekyBear 3 minutes ago

          So don't install Chrome.

        behnamoh 18 minutes ago

        Saying that Siri "works" is peak Apple fanboism.

      swozey 12 minutes ago

      I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.

  • behnamoh 28 minutes ago

    Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.

      doawoo 25 minutes ago

      I'd argue that a lot of developers can't determine if an LLM generated command is actually safe or not.

      wartywhoa23 24 minutes ago

      Ah, if only that meant that there'll be less slop in the macOS code itself..

      NamlchakKhandro 18 minutes ago

      Apple hates developers

        pjmlp 6 minutes ago

        They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.

  • arialdomartini 32 minutes ago

    Stop the curl | bash insanity.

    https://nocurlbash.com/#en

      1over137 24 minutes ago

      “You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.

        jtrueb 20 minutes ago

        Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.

        tmpz22 17 minutes ago

        Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

        Its a different threat model. You should not curl bash.

      maccard 9 minutes ago

      What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode

      packeted 11 minutes ago

      Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.

        swozey 9 minutes ago

        They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.

      demibabs 31 minutes ago

      Good message but AI generated text is so grating to read.

      mogwire 11 minutes ago

      I bet this is the guy on the call who has to correct someone who calls them SSL certs.

      Excuse me, they are TLS certs.

      Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs

      aaomidi 13 minutes ago

      This isn’t really that much of an issue when we have tls tbh.

      Like I get why it’s bad, but also homebrew package installation is a more organized version of this.

      Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…

      shujito 30 minutes ago

      there's a homebrew alternative

      hypeatei 11 minutes ago

      > If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.

      They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.